Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Onnx Directory Traversal vulnerability

GHSA-whh8-fjgc-qp73 · CVE-2024-27318 · PYSEC-2024-222

Published · Modified

Description

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.

Ready to move

Start Securing

Free, no credit card | First findings in minutes